Nearly 20 US state-run health insurance exchanges include ad trackers that send user data like race and citizenship info to companies like Meta, TikTok, Google (Bloomberg)
Nearly 20 state-run health insurance exchanges are transmitting sensitive personally identifiable information—including race, citizenship status, and health data—to major ad tech companies like Meta, TikTok, and Google through embedded trackers, creating significant regulatory, compliance, and reputational risks for IT organizations managing public-sector healthcare systems. This data exposure violates privacy expectations, increases vulnerability to regulatory penalties under HIPAA and state privacy laws, and demonstrates inadequate third-party vendor management and web governance controls. CIOs must immediately audit their digital properties for unauthorized trackers, implement stricter data governance policies, and establish vendor management frameworks to prevent future breaches of sensitive citizen data.
